From d6c9c8d66619f60713d1f22e0ef781020fe0f9a6 Mon Sep 17 00:00:00 2001 From: jochen Date: Sun, 13 Sep 2026 01:10:45 +0200 Subject: [PATCH] postgres builds its own runtime, like any other module MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Its provisioner container named an image nobody could produce — a zero digest placeholder. It names an artifact instead, and the module says how to build it, so the mesh can make the database provider the catalogue needs. --- modules/postgres/Dockerfile | 28 ++++++++++++++++++++++++++++ modules/postgres/module.json | 19 ++++++++++++++++--- 2 files changed, 44 insertions(+), 3 deletions(-) create mode 100644 modules/postgres/Dockerfile diff --git a/modules/postgres/Dockerfile b/modules/postgres/Dockerfile new file mode 100644 index 0000000..8faa5d5 --- /dev/null +++ b/modules/postgres/Dockerfile @@ -0,0 +1,28 @@ +# postgres's runtime: the tool runtime, carrying this module's compiled provisioner, tools and +# event consumer. +# +# **Built from this module's own directory and nothing else.** The sdk is in the base image, so +# nothing is copied out of a neighbouring checkout — which is what lets the mesh build this from a +# repository and a path (novox/hq ADR 0069) rather than only on a workstation that happens to have +# the siblings. +# +# The base is named by ARG so it can be pinned to a digest the mesh's registry assigned. A tag would +# make this runtime's contents depend on what somebody last pushed under that name. +ARG RUNTIME_BASE=127.0.0.1:5000/mesh-tool-runtime@sha256:d4d793c828a5f563fdd8f49e5c6026d17b308a3f7a13c589849188362e4c7415 + +FROM ${RUNTIME_BASE} AS build +# Compiled under /app/modules so `@novox/mesh-sdk` resolves upward into the base's own +# node_modules — the module is compiled against exactly the sdk it will run against. +WORKDIR /app/modules/postgres +COPY . . +# The compiler is invoked by its real path rather than through node_modules/.bin, whose entries are +# symlinks to a launcher that requires its library relatively — resolved away when the base image +# was assembled. +RUN node /app/node_modules/typescript/bin/tsc client.ts index.ts provisioner/index.ts tools/index.ts \ + --module NodeNext --moduleResolution NodeNext --target ES2022 --outDir dist + +FROM ${RUNTIME_BASE} +COPY --from=build /app/modules/postgres/dist /app/modules/postgres/dist +# Which of the three the container runs is the declaration's business, said in its `args` — one +# image, because they are one module and share a client. +ENV MESH_TOOL_MODULES=/app/modules/postgres/dist/index.js diff --git a/modules/postgres/module.json b/modules/postgres/module.json index e6d9089..a161300 100644 --- a/modules/postgres/module.json +++ b/modules/postgres/module.json @@ -102,7 +102,6 @@ "id": "runtime", "type": "container", "name": "mesh-postgres", - "image": "mesh-runtime-postgres@sha256:0000000000000000000000000000000000000000000000000000000000000000", "network": "postgres", "volumes": [ "/var/lib/mesh/postgres/broker:/run/secrets/broker:ro", @@ -114,7 +113,21 @@ "MESH_PROVISION_PASSWORD_FILE": "/run/secrets/superuser", "MESH_BROKER_FILE": "/run/secrets/broker", "MESH_RECEIVES": "/var/lib/postgres/grants/mesh.json" - } + }, + "artifact": "runtime", + "args": [ + "run", + "/app/modules/postgres/dist/provisioner/index.js" + ] } - ] + ], + "build": { + "artifacts": [ + { + "name": "runtime", + "kind": "image", + "from": "Dockerfile" + } + ] + } }